安全模式下用System Repair Engineer在启动中删除
<wdfmgr32><C:\WINNT\system32\wdfmgr32.exe> []
<mhs2><C:\DOCUME~1\fz\LOCALS~1\Temp\1.exe> []
<wlzs2><C:\DOCUME~1\fz\LOCALS~1\Temp\72812.exe> []
<wlzs><C:\DOCUME~1\fz\LOCALS~1\Temp\2.exe> []
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{54D9498B-CF93-414F-8984-8CE7FDE0D391}><C:\Program Files\ewido anti-malware\shellhook.dll> []
<{6E44887F-5214-41F2-AB46-4728735C4CC6}><C:\Program Files\Internet Explorer\PLUGINS\System64.sys> []
删除
[cdnie]
<C:\Documents and Settings\fz\「开始」菜单\程序\启动\cdnie.lnk><H>
服务
删除
[COM Ent System / EeSystem]
<C:\WINNT\System32\service.exe><N/A>
[Event_Log / Event log]
<C:\Documents and Settings\All Users\「开始」菜单\程序\heelp\kv.exe><N/A>
Explore / Explore]
<C:\WINNT\Explore.exe><N/A>
[GrayPigeon_Hacker.com.cn / GrayPigeon_Hacker.com.cn]
<C:\WINNT\Hacker.com.cn.exe><N/A>
[SYSTEM / SYSTEM]
<C:\WINNT\SVCHOST.exe><N/A>